MS reveals second DirectShow vuln

The flaw in DirectShow - the second in just over a month - leaves Windows XP and Server 2003 systems vulnerable to attack.

Microsoft is warning its users of a currently unpatched hole in the ActiveX video streaming functionality of DirectShow.

According to CNet, the vulnerability is already seeing “limited attacks” and can result in arbitrary code execution under the privilege of the currently logged in user when a malicious website is visited.

This marks the second major security breach in DirectShow in the past month, and as the issue affects both consumer-level and enterprise-grade Windows installations will once again be causing system administrators to wonder why something so clearly desktop oriented as DirectShow is installed by default in Windows Server 2003.

The report on Microsoft's Security Reponse blog indicates that both Windows XP and Windows Server 2003 are affected – although changes in the way Windows Vista and Windows 7 operate mean that the issue is avoided. Describing the affected ActiveX control as having no “by-design uses” - which raises the question of why it's there in the first place – Microsoft's current advice is to set the kill bits which will prevent the ActiveX control from being loaded pending an official patch.

Perhaps the more interesting way to obviate risk from this latest vulnerability is to upgrade to Internet Explorer 8: reports state that only IE6 and IE7 are affected.

Do you believe that Microsoft needs to seriously investigate why it's installing vulnerable end-user technologies such as DirectShow onto a server operating system, or are you just pleased that the company has quickly identified a work-around? Share your thoughts over in the forums.
Quote perplekks45 7th July 2009, 11:41
Quote:
Do you believe that Microsoft needs to seriously investigate why it's installing vulnerable end-user technologies such as DirectShow onto a server operating system,
One would think that MS know that one of the main attacking points for Windows-haters is that it's bloated, so they should make sure to not install stuff they don't need.
Windows Live Essentials was a step in the right direction.
Quote Phil Rhodes 7th July 2009, 14:18
My first thought was "vuln"?
Quote Coldon 7th July 2009, 14:37
notice that it only affects XP and server 2003...
Quote perplekks45 7th July 2009, 18:26
Quote:
Originally Posted by Coldon
notice that it only affects XP and server 2003...
Does that make it better or worse? :|
Quote sub routine 8th July 2009, 06:50
microtw@ts practically rule the world it wouldn`t be rash to presume they have many secret service agents working for them creating these loops. If they haven`t been allready i would think it was a rather large resource that has been missed.
Log in

You are not logged in, please login with your forum account below. If you don't already have an account please register to start contributing.